ZeroHour

CVE-2019-14973

CVSS 3.1
6.5 medium
EPSS
4%p90
Published
()
Modified
Description

_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for example, lead to an application crash.

Vendors
libtiffdebianfedoraprojectopensuse
Products
libtiff, debian linux, fedora, leap
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.